Microsoft Windows BitLocker Security Feature Bypass Vulnerability
Vulnerability
A vulnerability in Windows BitLocker allows an unauthorized attacker to bypass the Device Encryption feature on the system storage device. This issue arises from the missing ability to patch ROM code, enabling physical attacks to exploit the vulnerability and gain access to encrypted data. The vulnerability affects multiple Windows versions, including Windows 10, Windows 11, Windows Server 2016, Windows Server 2022, and Windows Server 2019.
Impact
Exploitation of this vulnerability could lead to unauthorized access to encrypted data by bypassing the BitLocker Device Encryption feature.
Remediation
Users can download the security update for this vulnerability via the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5066835, KB5066836, KB5066791, KB5066780, KB5066586, and KB5066793.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
